Description
A type confusion issue in seroval.fromJSON() allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver records.
Recommendation
Update the seroval package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.5.2
- Patched version(s): 1.5.3
References
Could your website be exposed too?
SmartScanner can check your website for seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry - CVE-2026-59891
- Qwik City has array method pollution in FormData processing allows type confusion and DoS - CVE-2026-32701
- PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `f - CVE-2026-69153
- Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial - CVE-2026-33940


